mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2024-11-01 13:01:15 +00:00
6fc17ad37b
- Use TXT records in order to determine the latest available version. - This addresses a valid privacy issue, as with HTTP requests the server can keep track(estimated) of how many instances are using Forgejo, with DNS that's basically not possible as the server will never receive any data, as the only ones receiving data are DNS resolvers. (cherry picked from commit0baefb546a
) (cherry picked from commite8ee41880b
) (cherry picked from commit7eca4f3bf1
) (cherry picked from commit6dde3992dc
) (cherry picked from commitfb3a37fbfc
) (cherry picked from commit8304af1e9d
) (cherry picked from commit0543a7d12a
) (cherry picked from commitc3a22933b7
) (cherry picked from commite243707694
) (cherry picked from commit7eb6d1bcf7
) (cherry picked from commit1d7b9535cd
) (cherry picked from commit05920dce67
) (cherry picked from commitf173f27d7c
) (cherry picked from commit90e1c9340e
) (cherry picked from commitde68610ea7
) (cherry picked from commit8d5757ea04
) (cherry picked from commitc7a7fff316
) (cherry picked from commit39ac8b8fc1
) (cherry picked from commit9889203301
) [PRIVACY]: Adjust update checker description - Resolves #323 - Adjust the description of the update check function on the installation page to describe the privacy method instead of the HTTP method by checking gitea.io (cherry picked from commit61eae5b105
) (cherry picked from commit091def20a1
) (cherry picked from commitd5d11bf45a
) (cherry picked from commit71863d4707
) (cherry picked from commit11ece4aab1
) (cherry picked from commitafdd7e714f
) (cherry picked from commit39170e2f1d
) (cherry picked from commit4b3a52aab8
) (cherry picked from commit9d763c5fc8
) (cherry picked from commit638db15482
) (cherry picked from commita52bfdd8e7
) (cherry picked from commitdc93d00e85
) (cherry picked from commit0bc4b3508c
) (cherry picked from commit3f760d85a4
) (cherry picked from commitecc2716785
) (cherry picked from commit6334d5677e
) Conflicts: modules/updatechecker/update_checker.go UpdateRemoteVersion now has a context argument. However, in the updated code from Gitea the context comes from the HTTP request and does not actually provide any useful context. Replace that with context.Background() (cherry picked from commitca2200767e
) (cherry picked from commitf46feca224
) (cherry picked from commita800a66ca8
) (cherry picked from commit21f017454e
) (cherry picked from commit762d18e09a
) (cherry picked from commit6d28e120c1
) (cherry picked from commit4fcd7e7cbf
) (cherry picked from commit9516285112
) (cherry picked from commit0dd752a262
) (cherry picked from commitb1f1af7fe0
) (cherry picked from commit71937deaa5
) (cherry picked from commit93e41a7823
) (cherry picked from commitf497ed30cf
) (cherry picked from commitbff3346f7d
) (cherry picked from commit906ae19c0f
)
144 lines
3.7 KiB
Go
144 lines
3.7 KiB
Go
// Copyright 2021 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package updatechecker
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"io"
|
|
"net"
|
|
"net/http"
|
|
"strings"
|
|
|
|
"code.gitea.io/gitea/modules/json"
|
|
"code.gitea.io/gitea/modules/proxy"
|
|
"code.gitea.io/gitea/modules/setting"
|
|
"code.gitea.io/gitea/modules/system"
|
|
|
|
"github.com/hashicorp/go-version"
|
|
)
|
|
|
|
// CheckerState stores the remote version from the JSON endpoint
|
|
type CheckerState struct {
|
|
LatestVersion string
|
|
}
|
|
|
|
// Name returns the name of the state item for update checker
|
|
func (r *CheckerState) Name() string {
|
|
return "update-checker"
|
|
}
|
|
|
|
// GiteaUpdateChecker returns error when new version of Gitea is available
|
|
func GiteaUpdateChecker(httpEndpoint, domainEndpoint string) error {
|
|
var version string
|
|
var err error
|
|
if domainEndpoint != "" {
|
|
version, err = getVersionDNS(domainEndpoint)
|
|
} else {
|
|
version, err = getVersionHTTP(httpEndpoint)
|
|
}
|
|
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
return UpdateRemoteVersion(context.Background(), version)
|
|
}
|
|
|
|
// getVersionDNS will request the TXT records for the domain. If a record starts
|
|
// with "forgejo_versions=" everything after that will be used as the latest
|
|
// version available.
|
|
func getVersionDNS(domainEndpoint string) (version string, err error) {
|
|
records, err := net.LookupTXT(domainEndpoint)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
if len(records) == 0 {
|
|
return "", errors.New("no TXT records were found")
|
|
}
|
|
|
|
for _, record := range records {
|
|
if strings.HasPrefix(record, "forgejo_versions=") {
|
|
// Get all supported versions, separated by a comma.
|
|
supportedVersions := strings.Split(strings.TrimPrefix(record, "forgejo_versions="), ",")
|
|
// For now always return the latest supported version.
|
|
return supportedVersions[len(supportedVersions)-1], nil
|
|
}
|
|
}
|
|
|
|
return "", errors.New("there is no TXT record with a valid value")
|
|
}
|
|
|
|
// getVersionHTTP will make an HTTP request to the endpoint, and the returned
|
|
// content is JSON. The "latest.version" path's value will be used as the latest
|
|
// version available.
|
|
func getVersionHTTP(httpEndpoint string) (version string, err error) {
|
|
httpClient := &http.Client{
|
|
Transport: &http.Transport{
|
|
Proxy: proxy.Proxy(),
|
|
},
|
|
}
|
|
|
|
req, err := http.NewRequest("GET", httpEndpoint, nil)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
resp, err := httpClient.Do(req)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
defer resp.Body.Close()
|
|
body, err := io.ReadAll(resp.Body)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
type respType struct {
|
|
Latest struct {
|
|
Version string `json:"version"`
|
|
} `json:"latest"`
|
|
}
|
|
respData := respType{}
|
|
err = json.Unmarshal(body, &respData)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
return respData.Latest.Version, nil
|
|
}
|
|
|
|
// UpdateRemoteVersion updates the latest available version of Gitea
|
|
func UpdateRemoteVersion(ctx context.Context, version string) (err error) {
|
|
return system.AppState.Set(ctx, &CheckerState{LatestVersion: version})
|
|
}
|
|
|
|
// GetRemoteVersion returns the current remote version (or currently installed version if fail to fetch from DB)
|
|
func GetRemoteVersion(ctx context.Context) string {
|
|
item := new(CheckerState)
|
|
if err := system.AppState.Get(ctx, item); err != nil {
|
|
return ""
|
|
}
|
|
return item.LatestVersion
|
|
}
|
|
|
|
// GetNeedUpdate returns true whether a newer version of Gitea is available
|
|
func GetNeedUpdate(ctx context.Context) bool {
|
|
curVer, err := version.NewVersion(setting.AppVer)
|
|
if err != nil {
|
|
// return false to fail silently
|
|
return false
|
|
}
|
|
remoteVerStr := GetRemoteVersion(ctx)
|
|
if remoteVerStr == "" {
|
|
// no remote version is known
|
|
return false
|
|
}
|
|
remoteVer, err := version.NewVersion(remoteVerStr)
|
|
if err != nil {
|
|
// return false to fail silently
|
|
return false
|
|
}
|
|
return curVer.LessThan(remoteVer)
|
|
}
|